CST CRF · GRC Advisory · ICT Licensees
Quick Answer
GHS helps Saudi ICT licensees get and stay compliant with CST’s Cybersecurity Regulatory Framework (CRF) through a structured engagement: a gap assessment against the six CRF control domains at your target Compliance Level, a prioritized roadmap from CL1 through CL3, hands-on support building the evidence CST assessors expect, and a full pre-audit simulation before the real thing.
We work with licensees at every stage — from a first CL1 baseline to organizations stuck on the CL2-to-CL3 transition — and for licensees that are also NCA ECC or CCRF in scope, we build one control map that covers every applicable framework instead of running separate projects per regulator.
If you’re a CST-licensed ICT Service Provider in Saudi Arabia, you already know CRF isn’t optional — it’s covered elsewhere on our blog in our full CST CRF explainer. What that guide doesn’t cover is the part licensees actually ask us about first: who does the work of getting compliant, and how. This post is that answer.
Three recurring situations bring licensees to us:
We benchmark your current controls against all six CRF domains — governance, asset management, risk management, logical security, physical security, and third-party security — at your target Compliance Level.
A prioritized, sequenced plan — governance quick wins first, then formal risk management, then continuous-monitoring capability — scoped to your team’s actual capacity, not a generic checklist.
Hands-on support producing the artifacts assessors actually ask for — policies, risk registers, access logs, monitoring records — not just advice on what to write.
A full dry run of the CST assessment experience, surfacing weak answers and missing evidence while there’s still time to fix them.
Most large telecom operators and hosting providers aren’t just CRF-scoped — many are also designated Critical National Infrastructure under NCA ECC, and many also offer cloud services that pull in the Cloud Computing Regulatory Framework (CCRF). Running three separate compliance tracks for overlapping controls — governance, access management, physical security — wastes time and multiplies audit fatigue. GHS builds a single control map spanning every framework a licensee is actually subject to, so evidence gathered once satisfies CRF, ECC, and CCRF assessments alike. We track this evidence on an ongoing basis inside ComplyOS, so the next assessment cycle is a status check, not a rebuild.
GHS Perspective
The licensees who move fastest through CRF are the ones who treat CL1 through CL3 as one continuous program with a single owner — not three separate certification sprints handed off between teams. That’s the model we build every engagement around.
| Stage | Typical Duration | Outcome |
|---|---|---|
| CL1 baseline | 4–6 weeks | Gap assessment + remediation plan for foundational controls |
| CL2 build-out | 2–4 months | Formal risk management, deeper logical/physical controls |
| CL3 maturity | Ongoing program | Continuous monitoring, metrics-driven improvement |
Where you start on this table depends entirely on where your program stands today — a gap assessment in week one tells us exactly which row you’re starting from.
GHS benchmarks your current controls against CRF’s six domains at your target Compliance Level and hands you a prioritized roadmap — no generic checklist, no guesswork.